Search the user directory. The user directory (usernames + emails) is
Search the user directory. The user directory (usernames + emails) is
sensitive (CAT-4), so results are scoped via AuthService::org_visible_user_ids
— OSS returns None (unrestricted, no org hierarchy to scope by); EE
restricts non-admin callers to their own department/team, same as the MCP
share-target picker (oss/mcp-gateway’s search_share_targets_view).
An exact username/display-name match bypasses that scope, mirroring
resolve_share_target/departments.rs::resolve/teams.rs::resolve —
a caller who already knows exactly who they’re looking for (e.g. a
connector owner sharing outside their own team) can still find them by
typing the full name, they just can’t browse/enumerate people outside
their scope via a partial query.
Query Parameters
Search term, minimum 2 characters.
